Skip to content

fix(connect): stop reporting a loading cloud session as a sign-in change - #11013

Open
Project516 wants to merge 1 commit into
pingdotgg:mainfrom
Project516:fix/connect-pending-session
Open

Project516 wants to merge 1 commit into
pingdotgg:mainfrom
Project516:fix/connect-pending-session

Conversation

@Project516

@Project516 Project516 commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Problem

While a client is still loading its T3 Connect cloud session, every relay authorization attempt fails with Your cloud sign-in changed. Sign in again to authorize the environment. The sign-in has not changed, and signing out and back in does nothing. The connection parks in a blocked state instead of retrying, and the status line carries the wrong reason into Failed to connect. Reconnecting.... On a slow or busy host the loading window is long enough to hit routinely.

On web and mobile the cloud identity is the managedRelaySessionAtom value. It stays null until Clerk loads and ManagedRelayAuthProvider finishes activating, and the connection supervisor can start attempts before then.

Change

In packages/client-runtime/src/authorization/service.ts, an attempt that starts with no cloud identity now fails with a ConnectionTransientError with reason session-pending and the detail Waiting for the T3 Connect sign-in to load. The supervisor retries it with normal backoff instead of treating it as blocked. session-pending is added to the transient reasons in connection/model.ts.

sessionChanged() still applies when an identity captured at the start of an attempt later disappears or is replaced, so a real sign-out or account switch is still blocked. A real sign-out does not retry forever, because both auth providers remove relay environments from the catalog when the account goes away.

The 3s cached-endpoint websocket ticket timeout mentioned in the issue is a separate tuning question and is not changed here.

Scope and approval

Fixes #11004, which a maintainer triaged and accepted, confirming the bug on main and pointing at sessionChanged() for a None identity (triage).

Verification

vp test run packages/client-runtime/src/authorization/layer.test.ts on this branch: 24 passed. One new test covers the loading window. Authorizing with no identity yields the transient session-pending error, and the same call succeeds once the session arrives. The existing logout-during-renewal tests still expect the blocked error. One existing assertion now expects the transient error because it authorizes with no identity at all. I later rebased onto main as of October 5 with no conflicts and did not rerun the tests locally, so CI covers the rebased commit.

To confirm the tests exercise the bug, I ran the same test file against main's service.ts and model.ts. Two tests fail, receiving ConnectionBlockedError: Your cloud sign-in changed... where ConnectionTransientError with reason session-pending is expected:

FAIL  layer.test.ts > RemoteEnvironmentAuthorization > retries instead of blocking while the cloud session has not loaded
FAIL  layer.test.ts > RemoteEnvironmentAuthorization > requires fresh credentials after signing back into the same account
AssertionError: expected ConnectionBlockedError: Your cloud sign-i… to match object { _tag: 'ConnectionTransientError', reason: 'session-pending' }

tsc --noEmit in packages/client-runtime is clean.

Not checked: a live reproduction in a client. That needs a signed-in T3 Connect account and a relay environment on a host slow enough to widen the loading window, which I could not set up here. The only visible difference is the connection status detail text during the loading window: Waiting for the T3 Connect sign-in to load. instead of the sign-in-changed message, followed by a normal reconnect.

Claude Opus 5.5 via Claude Code in T3 Code.

@cursor

cursor Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 10, 2026
@macroscopeapp

macroscopeapp Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This focused fix changes cloud-session authorization from a blocked state to transient retry while the session is loading, while preserving blocking for identity changes during an attempt. Because production authorization code is modified, the sensitive auth-directory rule calls for additional scrutiny.

No code changes detected at e06fab3. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Important

Review skipped

We couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting @coderabbitai full review.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: ac56e8aa-b410-43f0-b4bd-3a7e09a4cb4e


📥 Commits

Reviewing files that changed from the base of the PR and between b7b3ef1 and ceabaf43ce04b80537f31e56a86dd2296512ed68.


📒 Files selected for processing (3)
  • packages/client-runtime/src/authorization/layer.test.ts
  • packages/client-runtime/src/authorization/service.ts
  • packages/client-runtime/src/connection/model.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 7 remain after this review.



📝 Walkthrough

Walkthrough

Authorization now reports session-pending while cloud-session identity loading is incomplete. It preserves sessionChanged for captured identities that later change or disappear, and tests verify retry behavior.

Changes

Authorization session state

Layer / File(s) Summary
Transient session handling
packages/client-runtime/src/connection/model.ts, packages/client-runtime/src/authorization/service.ts, packages/client-runtime/src/authorization/layer.test.ts
Adds the session-pending transient reason. DPoP authorization uses it when no session identity is available, while changed captured identities still use sessionChanged. Tests cover pending authorization, successful retry, and signed-out behavior.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Severity of issue fixed: Low

Suggested reviewers: juliusmarminge, t3dotgg


Merge Risk: ⚪ Minimal · up to ceaba

Cloud-session loading now retries as a transient connection condition instead of showing a sign-in-change error, while genuine identity changes remain blocked. The change is covered by focused authorization tests and is ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The PR addresses issue [#11004] by returning a retryable session-pending error when identity loading has not completed, while preserving the blocked sign-in-change behavior for identities that change …
Out of Scope Changes check ✅ Passed The changes are limited to authorization behavior, the transient error model, and focused tests required for the linked issue. No unrelated code changes are present.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Title check ✅ Passed The title clearly and concisely describes the main change: a loading cloud session is no longer reported as a sign-in change.
Description check ✅ Passed The description covers the problem, change, scope and approval, and verification. It identifies the test results and the live-reproduction limitation.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests



Comment @coderabbitai help to get the list of available commands.

@Project516
Project516 force-pushed the fix/connect-pending-session branch from ceabaf4 to f0b2a5e Compare September 12, 2026 17:20
@Project516
Project516 force-pushed the fix/connect-pending-session branch from f0b2a5e to fd75b10 Compare September 23, 2026 17:08
@Project516
Project516 force-pushed the fix/connect-pending-session branch from fd75b10 to 9f4e1c4 Compare October 1, 2026 13:44
@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 1, 2026 — with ChatGPT Codex Connector
@Project516
Project516 force-pushed the fix/connect-pending-session branch 2 times, most recently from 9389164 to e06fab3 Compare October 6, 2026 01:05
Before the web or mobile client finishes loading its Clerk session, the relay
authorization path saw no cloud identity and failed with the blocked error
"Your cloud sign-in changed", parking the supervisor and sending users to fix
an auth problem that did not exist. On a slow host this window is easy to hit.

A missing identity at the start of an attempt now fails with a transient
session-pending error so the supervisor keeps retrying. A captured identity
that goes away or changes mid-attempt still blocks as a sign-in change.

Closes pingdotgg#11004
@Project516
Project516 force-pushed the fix/connect-pending-session branch from e06fab3 to 97efee6 Compare October 9, 2026 21:41

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: T3 Connect reports "Your cloud sign-in changed" when the host is just overloaded

2 participants